Effective email policies: Why enforcing proper use is critical to security

Acceptable use policy and IT securityconsidered potentially malicious) should not be received
While banning staff from sending or receiving personalor sent. The dissemination of illegal, offensive or other
emails is unrealistic, organizations can set boundariesinappropriate content should also be prohibited.
that define reasonable, excessive or inappropriate use,Employees should understand that companies are
through a comprehensive, updated and enforced emailobliged to report any unlawful behavior to the
acceptable use policy (AUP). A well-articulated emailauthorities, and that inappropriate activity can invoke
AUP addresses four core security and operationaldisciplinary proceedings. Some organizations may also
areas:choose to block access to web-based email services,
Compliancesuch as Hotmail and Gmail.
Safe working environmentAUP enforcement
Data leakageThe email AUP must be enforced if employees are to
Asset abuse.adhere to its rules. If they realize that their messages
A framework for corporate governanceare reviewed and stored – and then retrieved if
According to IDC Research 97 billion emails are sentneeded – employees might think twice before
worldwide each day1, and it is estimated that 80misusing the email system. An AUP should provide
percent of an organization’s operational recordstotal transparency about how an organization intends
are stored within the email infrastructure.to police its email system, ensuring that there are no
Governments around the world have responded tosurprises in the event of disciplinary action being
email’s growing use as a business-critical tool byinvoked.
introducing increasing levels of legislation governing theEnforcement through technology
security, storage and retrieval of email. Falling foul ofThe key to enforcement is the deployment of IT
such legislation not only damages an organization’ssecurity solutions capable of auditing everyday email
reputation, but can lead to fines, market de-listings and,use, spotting and tracking potential or confirmed
in extreme cases, prosecutions and prison sentencesviolations and notifying the appropriate managers if a
for senior management.violation has occurred. Although it is not necessary to
Keeping abreast of such legislation is challenging, andinform staff about the actual technology behind the
an AUP can help by providing a formal frameworksolutions deployed, it is worth explaining their top-level
that is easily reviewed, audited and enforced to ensurecapabilities.
compliance.*This is an example only. You should seek formal legal
Increasing complianceguidance when developing your own AUP.
Email is now central to the day-to-day operation ofEffective email policies: why enforcing proper use is
practically all organizations, regardless of size or sector.critical to security
Yet, while it is far too important to lock down, emailGateway email protection. Commonly deployed to
poses a large enough risk where it cannot be leftblock spam and malicious emails from entering
unregulated, especially as nearly all employees expectnetworks, gateway protection is highly effective at
a certain level of personal email use while at work.stopping suspicious or unwanted file attachments,
According to employers, however, it is their ownoffensive content and sensitive corporate information.
workforces that pose the greatest threat to securityThe leading solutions scan outbound and inbound
(figure 1).messages and attachments, ensuring that no
Effective email policies: why enforcing proper use isunauthorized content leaves the network.
critical to securityOrganizations can choose either to block or quarantine
Creating a safe working environmentthese emails, and administrators are automatically
An email AUP will promote a safe, productive workingnotified of attempted violations.
environment where employees can operate withoutEmail server protection. Security solutions at the email
fear of exposure to illegal, abusive, inappropriate orserver level protect against the internal circulation of
malicious material, such as pornography, jokes,unwanted content. By scanning inter-departmental
harassment or threats. By removing ambiguity andemails for jokes, photos, chain letters, malware and
ensuring all employees work to the same rules, theconfidential information which the recipient has no
policy sets clear expectations on what constitutesauthority to access, organizations can further bolster
acceptable email content.their email security. As with gateway protection, any
Preventing leakage of confidential informationviolation will be flagged up to the relevant managers.
According to IDC email is the number one source ofEndpoint protection. Organizations that permit access
leaked business information2. Additional researchto web-based mail over the corporate network should
confirms that most organizations are concerned aboutensure that all endpoint computers – desktops,
the loss of sensitive data via email.laptops and mobile devices – are running up-todate
Most of the time this can be accidental (thanks tosecurity software. Emails from webmail accounts
functions like Autofill) with research showing that halfbypass corporate gateway defences, and so have an
of employees have sent a message containingunobstructed route into an organization. Endpoint
sensitive or potentially embarrassing information byprotection closes this loophole by picking up any
mistake3. In addition, analysts The Radicati Groupmalicious or unwanted content that employees
found that 77 percent of users have forwardedattempt to download from this source.
business emails to their personal accounts in order toProcedures for reporting misuse
complete work when away from the office4. EvenEmployees should be encouraged to report the alleged
this most innocent of practices can leave anmisuse of email resources and a clear and anonymous
organization in breach of compliance regulations andprocedure must be put in place to facilitate this.
can place commercial information in unauthorizedSanctions for breaching AUP regulations
hands.All users must understand the potential consequences
Preventing asset abuseof not complying with the email
Excessive and/or inappropriate personal use of emailAUP. These consequences will depend on several
wastes bandwidth and placesstorage archives underfactors, including whether the abuser is a first or
strain, impacting on an organization’s ability to userepeat offender, whether the breach represents illegal,
its email infrastructure.offensive or merely wasteful behavior, the regulatory
This is particularly problematic when employeesenvironment in which the company operates and the
circulate non-critical attachments, such as familyfirm’s cultural outlook. The sanctions will relate to
photos or videos. Prohibiting or restricting this practicethe severity of the offense, ranging from verbal and
preserves the integrity of the email system and canwritten warnings, and on to dismissals.
extend the life of storage solutions. It also ensures thatWho is responsible for the AUP?
IT staff remain focused on their core responsibilitiesThe HR IT, and legal departments are all stakeholders
and do not spend time clearing personal emails fromin the creation and enforcement of an email AUP.
the system.Employees should also contribute to an AUP, enabling
What an AUP should covergreater transparency and buy-in and ensuring that
An AUP should set out exactly how an employee iseveryone is aware of its existence. At some
expected to use an organization’s email system,organizations, the CEO or other board members may
containing prescriptive advice on best practice andtake an active involvement, as they can be held
clearly defining prohibited behavior.personally liable for email misuse by any employee.
It is essential that regulations are explicitly stated andTypically, staff from all three departments should work
easily understood. The content of an AUP will varytogether to develop the policy, with specific
between organizations, reflecting their regulatoryresponsibilities divided as follows.
environment, email quantity, IT resources and culture.HR role
Some may choose to incorporate rules governingThe HR department owns the overall process of
email use into a wider AUP that covers all technologydeveloping an email AUP, taking responsibility for
use, from telephones to web browsing toawareness, distribution and training. Using data provided
photocopying.use is critical to securityby the IT department, and by responding to reports of
However, in general, an email AUP covers threemainalleged misuse, HR conducts audits to ensure that
elements:rules are observed, investigates suspected policy
Appropriate and inappropriate email usecontraventions, and implements disciplinary procedures.
Policy enforcementEffective email policies: why enforcing proper use is
Policy sanctions.critical to security
Areas that should always be covered include:IT role
Inbox managementBy using the security solution’s reporting features,
In response to the continued growth in email use,the IT team generates the forensic evidence needed
organizations should attempt to limit the volume ofto identify and log email abuse. The data gathered
messages stored in employee mailboxes. The numberrepresents the company’s principal source of
of emails held in archiving systems that capture bothsecurity intelligence, and can be pieced together to
internal and external mail should also be limited, ensuringanalyze each breach and pinpoint the staff responsible.
resources are not overloaded and allowing for easyThis information can then escalated to HR.
message retrieval.The IT department also advises HR on the changing
Circulation of attachmentscapabilities of the organization’s IT defenses. For
Users commonly view email as a quick method ofexample, if a new solution is deployed to scan
sharing content with colleagues. However, this practiceoutbound messages for sensitive material (e.g. credit
needlessly uses up bandwidth and archive space.card or social security numbers), the AUP might need
Instead, all attachments should be removed before anto be amended and email users might require additional
email is stored and saved on an appropriate server.training.
Additionally, employees should be instructed on how toLegal role
use shared network folders to circulate files internally,The in-house or external legal department ensures that
rather than attaching them to emails. Consider that onethe AUP is in line with legal and compliance
person sending a 5 MB attachment to five otherrequirements, and will advise HR to amend it if
employees results in more than 25 MB of email serverregulations change.
storage requirements. Placing this file on a sharedSummary
server and circulating a link to its location not onlyWhile the threat of spam and malware is usually linked
greatly reduces the size of the email, it preventsto inbound emails, an organization’s own users can
unnecessary duplication of files across multipleoften cause just as much or more damage through
locations.the emails they send or share.
Remote access of email servicesEmployees can be responsible for data leakage,the
Rules should be set governing remote access to thedissemination of inappropriate or offensive content, and
corporate email network, both from employees’consuming bandwidth through the unnecessary sharing
own computers and over the internet/public Wi-Fiof files, each of which represent a considerable threat
networks. Some organizations ban this practiceto the email network. To ensure that employees
altogether, while others permit it only if the computerrecognize these risks, organizations should implement a
accessing the network is certified as secure by, forcomprehensive email acceptable use policy which, to
example, a network access control (NAC) solution.be effective, requires enterprise-grade security
Personal/non-business critical use of emailsolutions for the gateway, the email server and all
File types categorized as non-business critical (forendpoint computers.
example, JPEGs, MP3s, executables and anything